Australia: data, AI and cyber laws
3 regulations in Australia that affect companies handling data: Australia Cyber Security Act (ransomware reporting), Australia Privacy Act, Australia Social Media Minimum Age. Part of APAC.
3 regulations
Add to calendar
- Australia Privacy Act
Australia
AmendedPrivacyChildrenNext: Dec 10, 2026 Children's Online Privacy Code must be registered
- In forceCybersecurityBreach notification
Effective Nov 30, 2024
- Australia Social Media Minimum Age
Australia
In forceChildrenOnline safetyEffective Dec 10, 2025
Upcoming deadlines
December 20262 deadlines
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
Past deadlines
January 20261 deadline
Ransomware reporting moves to compliance phase
The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.
December 20251 deadline
Social media minimum age obligation applies
Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.
June 20251 deadline
Statutory tort for serious invasions of privacy commences
Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.
May 20251 deadline
Ransomware payment reporting starts
Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.
December 20241 deadline
Most POLA Act 2024 amendments commence
Tiered penalties, infringement notices, OAIC powers, security and overseas-transfer clarifications and doxxing offences commence the day after Royal Assent.